Skip to content

Security1 publisherNot yet confirmed elsewhere2 min readPublished

Ten agencies tie China-linked intrusions across several sectors to Integrity Technology Group

Integrity Technology Group, a government-linked Chinese firm, enables China-linked hackers to breach US and foreign networks, ten agencies said. The advisory treats the firm and its crews as one set of actors, so a single hunt can span sectors.

The Watch · Security desk

How we use AISend a correction

What happened

  • The crews combine large-scale botnets, VPN infrastructure, living-off-the-land techniques and repositories of network exploitation tools, the advisory says.
  • Victims span US government, critical manufacturing, healthcare and IT, plus law enforcement, education, religious groups and organizations in Southeast Asia, Africa and North America.
  • The advisory's evidence was recovered from, and observed during, multiple FBI investigations related to Integrity Tech.
  • Integrity Tech is run for profit, acquires or builds cyber tools for sale as well as use, and employs people who break into victim networks directly.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • capability One sweep against infrastructure Integrity Tech hosts can surface intrusions a defender had filed under different actor names, because several crews draw on the same supplier.
  • exposure A clean result against the Integrity Tech indicators does not clear a network, since the advisory says the same crews also run operations not associated with the firm.
  • decision Law enforcement, education and religious organizations are on the victim list, so the hunt request applies to them as much as to the four named critical infrastructure sectors.

The advisory says activity matching the crews Integrity Tech enables is publicly known as Flax Typhoon, Ethereal Panda and Red Juliett, among other names [10]. A team that keeps separate case files under two of those names may be tracking customers of the same supplier. The agencies also warn that vendor groupings "may not be a 1:1 correlation to the US Government's methodology" [12]. Merging cases on a vendor label alone can pull in activity the government groups differently.

The advisory supports a cross-sector hunt for one toolkit, but its wording stops short of treating every match as the same operator. It calls the combination of tools unique [2]. It says the techniques themselves "are not unique to Chinese threat actors" [3]. On those terms, one botnet address or one living-off-the-land command in a log is a lead to check against the indicator list. The agencies publish that list as a separate download [13].

I'd expect the hosted infrastructure to be the part that repeats from victim to victim. Integrity Tech acquires and hosts infrastructure for the crews it enables [15]. Its services feed what the advisory calls "the larger Chinese cyber ecosystem, which aims to exfiltrate sensitive data from victims around the world" [14].

The FBI, CISA and NSA signed with the national cyber agencies of the UK, Australia, Canada and New Zealand [7]. Japan's National Police Agency and National Cybersecurity Office signed, as did Spain's Centro Nacional de Inteligencia [7]. Ten organisations in seven countries are on it [16]. They ask defenders to hunt for compromises from this activity and to harden against it and other Chinese government-linked targeting [8].

What to watch

  • Whether firms that track Flax Typhoon, Ethereal Panda and Red Juliett re-map those clusters to the government's Integrity Tech grouping.
  • Hunt results from the named victim sectors that match the published indicators, which would show how far one supplier's infrastructure reaches.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence62
Adoption
Insufficient
Hype gap+5
Incentives
Insufficient
Confidence58
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Integrity Technology Group, a China-based company with links to the Chinese government, enables China-linked threat actors to exploit US and foreign organization networks across multiple sectors using various tools and techniques.

    ReportedSupportedSource: Joint cybersecurity advisory, cisa.govView cited source
  2. [2]

    The threat actors use a unique combination of large-scale botnets, virtual private network (VPN) infrastructure, living-off-the-land (LOTL) techniques, and repositories of computer network exploitation (CNE) tools.

    ReportedSupportedSource: Joint cybersecurity advisory, cisa.govView cited source
  3. [3]

    Although these techniques are not unique to Chinese threat actors, the advisory details how the threat actors use them to support CNE activity.

    ReportedSupportedSource: Joint cybersecurity advisory, cisa.govView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. cisa.gov

    1 article · October 8, 2026

    Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Entities

Loading related stories